Claremont SecurityManaged compliance ยท Enterprise AI protection
// Broker_Channel / Controls_Remediation

For Brokers

Cyber applications stall on a short list of controls, and usually the same one. We close the gap and put it in writing, so your client can answer the questionnaire accurately and you can go back to the carrier with something that has changed.

Where applications stall

Every broker placing professional-lines cyber has had this conversation. The questionnaire comes back with a control the firm cannot honestly attest to, the submission sits, and there is nobody obvious to hand it to. The client is a fifteen-person accounting practice, not an IT shop. So it falls back on them, and it does not get done.

“Is MFA enforced on all email and remote access accounts?”

The most common stall. Often MFA is on for staff and off for the administrator and service accounts, which is the exclusion that matters. We enforce it properly and document every remaining exclusion by name.

“Is endpoint protection deployed across all devices?”

Usually the answer is yes and the evidence is a deployment log. We reconcile coverage against the firm's actual staff roster and confirm update status at each device, so the answer is one the firm can stand behind.

“Do you maintain a written information security program?”

Tax and accounting firms are already required to hold one under the FTC Safeguards Rule and IRS Publication 4557. Many hold a template nobody has opened. We produce a plan that describes the firm as it actually operates.

“Who at the firm is responsible for information security?”

Often nobody, formally. Where a firm engages us for standing oversight, that role has a name and a written scope, and there is someone who answers the security questionnaire rather than the client guessing at it.

How a referral works

01Send it over

Email the stalled question or forward the client. No form, no portal. If it is faster, call the direct line.

02We scope it, free

Thirty minutes with the firm on what they hold and what is already in place. If the gap is small enough that they can close it themselves, we tell them that.

03They get it in writing

A fixed fee and a defined deliverable before any work starts, and a written record of the controls at the end that the firm can attach to the application.

What it costs your client

Most referrals start with the Baseline Security Assessment, a fixed fee for two weeks of fieldwork from the day read-only access is granted. It produces a gap register mapped to 16 CFR Part 314 and IRS Publication 4557, each gap rated with a recommended owner by role and a target date.

The fee is credited in full against the implementation engagement that follows, if that engagement is executed within ninety days. We change nothing during an assessment, which is what keeps the findings independent of the firm that would remediate them.

Remediation is quoted separately, in writing, after the assessment. Nothing is billed hourly. Full engagement structure and fees.

What we do not do

Worth stating plainly, because a referral is your relationship on the line and you should know the edges before you make one.

  • We do not place or advise on coverage. Claremont is not an insurance producer. We work on the controls; the policy stays entirely with you.
  • We cannot promise a carrier will bind, or bind at a given price. Underwriting is the carrier's call. What we can do is make the firm's answers accurate and evidenced.
  • We do not tell a client what to write on an application. We document what is actually in place. The firm attests to its own answers.
  • We do not run a help desk or an around-the-clock response team. The platform monitors continuously. We review and respond to alerts on a defined business-hours cadence. Category II is oversight, documentation, and evidence on a defined cadence. Where a firm needs eyes on a screen overnight, they need a different vendor and we will say so.
  • Standing oversight requires Microsoft 365 Business Premium. Business Standard includes neither Intune nor Defender for Business, so that engagement cannot be delivered on it. Assessment and written-plan work has no such requirement.
  • We will tell your client when they do not need us. That happens, and it is better for you than a referral that produces an invoice and no change.

Who we work with

Accounting and tax practices first, and professional firms holding regulated client records more broadly. The typical fit is ten to twenty-five staff: large enough to be asked hard questions by clients, insurers, and the IRS, too small to justify a security hire.

Work is remote by default and Claremont serves firms across the United States, so a referral does not depend on the client being local to us or to you.

// Disclosure

Claremont Security LLC is not an insurance producer, agency, or broker, and is not affiliated with any carrier or brokerage. We do not sell, place, bind, or advise on insurance coverage of any kind.

No fee, commission, or other compensation is paid or received in connection with a referral, in either direction. A referral is a recommendation, not a commercial arrangement.

Nothing on this page is legal advice, insurance advice, or a representation about how any carrier will underwrite a given risk.

Send us a stalled application

Forward the question the client cannot answer, or just the client. We will tell you whether it is something we can close and roughly what it involves.